Reply to topic  [ 5 posts ] 
Alliance & Leicester protect customers against phishing 
Author Message
Legend

Joined: Sun Apr 26, 2009 12:30 pm
Posts: 45931
Location: Belfast
Reply with quote
http://www.pcadvisor.co.uk/news/index.c ... d=3205754&

_________________
Plain English advice on everything money, purchase and service related:

http://www.moneysavingexpert.com/


Thu Nov 05, 2009 10:44 pm
Profile
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
My bank has switched from the old TAN numbers to an electronic TAN generator - which uses the recipient bank account number plus the seed to help generate the unique TAN number for each transaction.

That means, even if I get phished, they can't use the information to drain the account - they would need a good sample of TANs on a single account number and seed to work out the sequence on the device.

I've heard some of the banks are working on a TAN generator app for the iPhone.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Fri Nov 06, 2009 5:27 am
Profile ICQ
What's a life?
User avatar

Joined: Fri Apr 24, 2009 10:21 am
Posts: 12700
Location: The Right Side of the Pennines (metaphorically & geographically)
Reply with quote
The other year many UK banks gave out personal pin reader for some online transactions. Why can't they set up the site to use those for part of the login details? That way you need the card, the pin and the personal details.

Image

_________________
pcernie wrote:
'I'm going to snort this off your arse - for the benefit of government statistics, of course.'


Fri Nov 06, 2009 8:52 am
Profile WWW
What's a life?
User avatar

Joined: Thu Apr 23, 2009 8:25 pm
Posts: 10691
Location: Bramsche
Reply with quote
I just need my pin number to log in.

The TAN generator is synced with my account and my bank card.

To make a transaction, I have to insert my bank card into the TAN (TransAction Numer) generator, give the seed number in and give the destination account number, the generator then provides the unique transaction number. The TAN is unique in time to my card, the provided seed AND the destination account.

If I enter the wrong account number - or a phishing site tried to substitute the account number on with their own - it would reject the whole transaction. The most they could do is look at my bank balance.

_________________
"Do you know what this is? Hmm? No, I can see you do not. You have that vacant look in your eyes, which says hold my head to your ear, you will hear the sea!" - Londo Molari

Executive Producer No Agenda Show 246


Fri Nov 06, 2009 9:16 am
Profile ICQ
I haven't seen my friends in so long
User avatar

Joined: Tue May 05, 2009 3:29 pm
Posts: 7173
Reply with quote
No way on this Earth am I going to install software supplied by my bank.

The PIN reader suggestion is a good idea though - although you can't perform any serious activities on my account without it anyway.

_________________
timark_uk wrote:
That's your problem. You need Linux. That'll fix all your problems.
Mark


Fri Nov 06, 2009 10:03 am
Profile
Display posts from previous:  Sort by  
Reply to topic   [ 5 posts ] 

Who is online

Users browsing this forum: No registered users and 9 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
cron
Powered by phpBB® Forum Software © phpBB Group
Designed by ST Software.